blob: 667d98b7bb98ee5265db336f66769b9b30324a7a [file] [log] [blame]
Zhiyi Zhang3f20f952020-11-19 19:26:43 -08001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
Davide Pesaventoe5b43692021-11-15 22:05:03 -05002/*
Tianyuan Yu13aac732022-03-03 20:59:54 -08003 * Copyright (c) 2017-2022, Regents of the University of California.
Zhiyi Zhang3f20f952020-11-19 19:26:43 -08004 *
5 * This file is part of ndncert, a certificate management system based on NDN.
6 *
7 * ndncert is free software: you can redistribute it and/or modify it under the terms
8 * of the GNU General Public License as published by the Free Software Foundation, either
9 * version 3 of the License, or (at your option) any later version.
10 *
11 * ndncert is distributed in the hope that it will be useful, but WITHOUT ANY
12 * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
13 * PARTICULAR PURPOSE. See the GNU General Public License for more details.
14 *
15 * You should have received copies of the GNU General Public License along with
16 * ndncert, e.g., in COPYING.md file. If not, see <http://www.gnu.org/licenses/>.
17 *
18 * See AUTHORS.md for complete list of ndncert authors and contributors.
19 */
20
21#include "detail/ca-configuration.hpp"
Davide Pesaventoe5b43692021-11-15 22:05:03 -050022
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080023#include <ndn-cxx/util/io.hpp>
Davide Pesaventoe5b43692021-11-15 22:05:03 -050024
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080025#include <boost/filesystem.hpp>
Davide Pesaventoe5b43692021-11-15 22:05:03 -050026#include <boost/property_tree/json_parser.hpp>
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080027
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040028namespace ndncert::ca {
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080029
30void
31CaConfig::load(const std::string& fileName)
32{
33 JsonSection configJson;
34 try {
35 boost::property_tree::read_json(fileName, configJson);
36 }
37 catch (const std::exception& error) {
38 NDN_THROW(std::runtime_error("Failed to parse configuration file " + fileName + ", " + error.what()));
39 }
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040040
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080041 if (configJson.begin() == configJson.end()) {
42 NDN_THROW(std::runtime_error("No JSON configuration found in file: " + fileName));
43 }
Davide Pesaventoe5b43692021-11-15 22:05:03 -050044 caProfile = CaProfile::fromJson(configJson);
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040045 if (caProfile.supportedChallenges.empty()) {
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080046 NDN_THROW(std::runtime_error("At least one challenge should be specified."));
47 }
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040048
49 // parse redirection section if present
tylerliuf2e6bb52020-12-13 13:23:05 -080050 redirection.clear();
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080051 auto redirectionItems = configJson.get_child_optional(CONFIG_REDIRECTION);
52 if (redirectionItems) {
53 for (const auto& item : *redirectionItems) {
54 auto caPrefixStr = item.second.get(CONFIG_CA_PREFIX, "");
55 auto caCertStr = item.second.get(CONFIG_CERTIFICATE, "");
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040056 if (caCertStr.empty()) {
Tianyuan Yu13aac732022-03-03 20:59:54 -080057 NDN_THROW(std::runtime_error("Redirect-to item's certificate cannot be empty."));
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080058 }
59 std::istringstream ss(caCertStr);
Davide Pesavento0dc02012021-11-23 22:55:03 -050060 auto caCert = ndn::io::load<Certificate>(ss);
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040061 if (!caPrefixStr.empty() && Name(caPrefixStr) != caCert->getIdentity()) {
Tianyuan Yu13aac732022-03-03 20:59:54 -080062 NDN_THROW(std::runtime_error("Redirect-to item's prefix and certificate does not match."));
63 }
64
65 auto policyType = item.second.get(CONFIG_REDIRECTION_POLICY_TYPE, "");
66 auto policyParam = item.second.get(CONFIG_REDIRECTION_POLICY_PARAM, "");
67 if (policyType.empty()) {
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040068 NDN_THROW(std::runtime_error("Redirect-to policy type expected but not provided."));
Tianyuan Yu13aac732022-03-03 20:59:54 -080069 }
70 auto policy = RedirectionPolicy::createPolicyFunc(policyType, policyParam);
71 if (policy == nullptr) {
72 NDN_THROW(std::runtime_error("Error on creating redirection policy"));
73 }
74 redirection.emplace_back(caCert, std::move(policy));
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080075 }
76 }
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040077
78 // parse name assignment if present
tylerliuf2e6bb52020-12-13 13:23:05 -080079 nameAssignmentFuncs.clear();
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080080 auto nameAssignmentItems = configJson.get_child_optional(CONFIG_NAME_ASSIGNMENT);
81 if (nameAssignmentItems) {
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040082 for (const auto& [key, val] : *nameAssignmentItems) {
83 auto func = NameAssignmentFunc::createNameAssignmentFunc(key, val.data());
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080084 if (func == nullptr) {
85 NDN_THROW(std::runtime_error("Error on creating name assignment function"));
86 }
tylerliuf2e6bb52020-12-13 13:23:05 -080087 nameAssignmentFuncs.push_back(std::move(func));
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080088 }
89 }
90}
91
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040092} // namespace ndncert::ca